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MEMORANDUM FOR: Deputy Director of Central Intelligence 


FROM: John F. Blake 
Deputy Director for Administration 


SUBJECT: Security Review - Interim Report 


REFBRENCE: Memorandum for DDA from DDCI, dated 
18 August 1978, Subject: A Request 
for a Security Review and Assessment 


1. Action Requested: None; for information only. 


Z. Background: Following the mid-August 1973 revelation 
that a former Agency employee had sold classified information 
to the Soviets, you directed a comprehensive review of the 
Agency's security policies and procedures and called for an 
interim report by 1 September 1978. Subsequently, the Director 
has expanded the scope of the interim report to include: 

(a) a cataloguing of specific improvements in the Agency's 
security program realized since his appointment and by his 
initiatives; and (b) a listing of procedures currently being 
initiated to further improve the security of classified infor- 
mation. Pursuant to those directions, this interim report is 
submitted. 


5. Staff Position: In April 1977, following the reve- 
lations of the Moore and Boyce/Lee espionage cases, a compre- 
hensive impact study was completed by the Office of Security. 

As 4 consequence, the Director caused several security initiatives 
and gave the necessary impetus to others which have been success- 
fully implemented to the enhancement of Agency and Intelligence 
Community security. Agency programs successfully implemented 
include: 


a. A rigorous staff personnel security 
reinvestigation program. 
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b. Expanded security education and reindoc- 
trination efforts throughout the Agency. 


c. Enhancement of appraisal criteria in 
Industrial Security Approvals. 


d. Initiation of the Industrial Contractor 
Polygraph Program. 


e. Increased spot checks of briefcases, 
packages and parcels at all Agency facilities in 
the Washington Metropolitan area. 


£. Initiation of a program of unannounced 
security audits of Agency contractor facilities. 


g- Initiation of research to enhance security 
movement of classified information via tamper-resistant 
security containers and to preclude unauthorized 
reproduction of documents via use of special paper, 
special inks and other techniques. 


h. A personal interest in and involvement by 
the Director and senior Agency managers in the 
adjudication and penalty assessment procedures 
involving Agency employees who have violated secu- 
rity regulations. 


Programs initiated by the Director to tighten the secu- ‘ 
of the Intelligence Community have included: ; 


a. The strengthening of the Director of Central 
Intelligence Security Committee as a focal point for 
reporting and tracking unauthorized disclosures and 
for raising security consciousness in the Community. 


b. Maintaining a freeze since 1 June 1977 on the 
total number of sensitive compartmented clearances 
throughout the Community. 


c. Initiation of a program to revalidate security 
clearances by effecting zero-based reviews in Intelli- 
gence Community and contractor facilities. 

d. Directing contracting and legal authorities to 


strengthen the security provisions of contracts between 
commercial firms and Intelligence organizations. 
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I can assure you the Director of Security has and 
is continuing to dedicate all available personnel resources, 
as well as his personal attention, to the programs outlined 
above. 


In accordance with your specific request of 18 August 
1978, a comprehensive review of the Agency's security policies 
and procedures has commenced. 


During the week of 21 August the organization and 
staffing of a Security Review Task Force was undertaken. 
The Task Force will approach the review in three segments. 
Hach segment staff will function under the leadership of a 
senior experienced officer. The segments will address, 
separately, Personnel Security, Physical Security, and Infor- 
mation Control and Protection. The magnitude of the task 
is awesome, and the Director of Security estimates a compre- 
hensive review will require a minimum of sixty (60) days. 


The Personnel Security Segment of the Task Force 
intends to investigate all periods of an employee's career 
from preemployment processing through post-employment counseling. 
It is their intent to survey personnel recruitment and assign- 
ment policies and procedures which are quite varied from 
directorate to directorate and from office to office. Although 
the emphasis in this segment will be on staff employees, the 
Task Force will also survey the several other types of individuals 
who are utilized by the Agency. The entire security clearance 
process from pre-field investigation to final adjudication will 
be reviewed, as will the vast number of policies and procedures 
that pertain during the employment phase. 


The employment phase topics include security indoctri- 
nation/reindoctrination; marriage, including marriage to an 
alien; outside activities; handling of misconduct incidents; 
counterintelligence review of high risk personnel and organiza- 
tional units; the reinvestigation program; security and 
suitability reviews for overseas candidates; Agency management 
responsibilities; and the Personnel Evaluation Board. Finally, 
the Agency's out-processing policies and procedures as well as 
current policies relative to post-employment counseling will be 
addressed under this segment. 


The Task Force will exclude from its review the 


operational security policy procedures and practices concerning 
those individuals who are utilized by the Directorate of 
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Operations in an operational and informational capacity such 
as double agents and clandestine sources. That policy is a 
DDO responsibility. 


The Physical Security Segment has an enormous task 
at hand. This segment will limit the scope of their review 
by concentrating primarily upon the physical security program 
as it is pursued within the Headquarters Building. The sub- 
Stantive areas which constitute the physical security program 
of the Agency can be examined in relation to operations within 
the Headquarters Building Meare a reasonable time frame. STATINTL 
Essentially our physical security policies and proce- 
dures at Headquarters have been adopted in our 
overseas facilities, and available resource and time constrain 
dictate that but cursory reference be given to the nature and 


scope of the cversc:: iia 
during the survey. Similarly, LS review Wi not specifically 


cover the physical security aspects of our industrial security 
program because that subject has been thoroughly reviewed during 
the past year. And finally, we consider the technical threat 

as well as the measures which have been implemented to counter 
this threat as beyond the scope of this review. 


QTATINTL 


The Physical Security Segment of the Task Force will 
address thoroughly the policies and procedures pertaining to: 
perimeter security; building security; access controls for 
all types of people from staff employees to vendors; badges; 
entry and exit inspection procedures; internal personnel control; 
storage of classified information; the Agency's guard program; 
intrusion detection systems and other monitoring equipment; 
after hours security procedures and the security violation pro- 
gram. 


The Information Control and Protection Segment pro- 
poses to review the application by CIA of directives and 
regulations governing the production, marking, classification, 
reproduction, transmission, inventory and overall control of 
classified information. These will be reviewed for current 
applicability to determine whether rules are being observed, 
and, if so, whether a significant measure of control results 
from their observance. The scope of this segment will include 
an inquiry into the level and efficiency of employee training 
in document control procedures; an examination of the possibility 
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of handling information at lower levels of classification 

or compartmentation; exploration of methods to reduce the 
amount of classified material retained in the Agency; inquiry 
into the efficacy of current ADP and microform information 
control, and the state of pre-planning for future information 
technology requirements. Finally, we intend to examine alter- 
native ways of controlling accountability for classified 
materials, including automated techniques. 


Obviously, to conduct the survey effectively, the 
Task. Force will require the complete cooperation of the 
Agency's population. For example, to meaningfully describe 
current procedures under the Personnel Security Segment is 
going to require close cooperation with several offices, 
especially the Office of Personnel and the Office of Medical 
Services. FPurthermore, several offices throughout the Agency 
are involved in the recruitment of personnel, and their 
cooperation will also be necessary. Consequently, it is recom- 
mended that you solicit the cooperation of all directorates 
with the members of the Task Force. 


The Task Force will approach its task by extensive 
documentary reviews, personal interviews both within and 
external to the Agency, and by discussion within the Task 
Force which will lead to a series of recommendations concerning 
the Agency's security program. The Task Force members have 
been exhorted to approach the task, particularly the recommen- 
dations, with absolute objectivity and personal integrity, as 
we view the review as an opportunity to assure our security 
policies and procedures are right for the time. 


We envision a final report to be submitted to you 
by 3 November 1978. We expect that report to be in four 
parts: (a) a description of current policies and procedures; 
(b) analysis of current policies and procedures; (c} conclusions; 
and (d) recommendations. 


The current review will be thorough. We anticipate 
specific recommendations pertaining to the restatement of the 
basic principle that Security is a command responsibility 
within the Agency, i.e., the responsibility of each manager 
and supervisor. Furthermore, we expect to relate the apparent 
deterioration in security discipline in the operating components 
to the reduction of professional security positions in those 
components over the past decade; in ten years the number of 
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Security careerists assigned to other TO's has dropped from 
160 to 89, thirty-nine of those positions were located over- 
seas and twenty-one were at Headquarters. These issues 
require orderly analysis before recommending specific changes. 


Nevertheless, the urgency of the present situation 
calis for the implementation of improved procedures and new 
initiatives prior to completion of the formal review. Towards 
that end the following actions have been taken: 


{a} Commencing 11 September 1978 the briefcase, 
package inspection program will be expanded and con- 
ducted by the Federal Protective Officers on a routine 
basis seven days a week and twenty-four hours a day. 


(b) Commencing immediately, systematic counter- 
intelligence procedures will be established by the 
Office of Security to investigate employee accesses 
to secure areas outside of normal duty hours and to 
review the pattern of employee after-hours accesses 
to Headquarters area buildings. 


(c) The Office of Security currently has ordered 
active studies into two methods of controlling document 
reproduction. One concept involves the modification 
of reproduction equipment to house a badge reader 
which would maintain accountability for all copies 
made at least to the extent of maintaining an audit 
trail of an individual employee's use of the equipment. 
The other concept involves development of a paper or 
print process which is not copiable. 


(d) The Deputy Directors of the Agency are being 
directed, immediately, to establish positive, account- 
able document controls for particularly sensitive 
materials under their cognizance. 


(e} Arrangements are being finalized for the 
Office of Security to conduct a series of briefings 
of senior staffs throughout the Agency. The briefings 
will comprehensively review security problems discovered 
during the past several months through the reinvesti- 
gation program, briefcase inspection program, etc., 
and will reemphasize the command and managerial respon- 
sibility in implementing sound security practices. 
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(£f) The Office of Security is reminding Agency 
managers that personnel are available as speakers, 
panelists, consultants, etc, to assist command chan- 
nels in the security education and reindoctrination 
of small employee groups. As you know, the Office 
of Security recently completed a formal reindoctri- 
nation of the Agency population in a number of 
presentations to large audiences. 


4. Conclusion: In accordance with the reference, I 
assure you that the Security Review is receiving the highest 
priority and my personal attention. The scope of the task, 


in my opinion, fully justifies a 3 November 1978 final reporting 
date. 


qepsohin F Blake 


Jonn F. Blake 
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